專案

一般

配置概況

動作

專案資訊 #1066

進行中

專案資訊 #1064: 2025-PenTest

Domain Admin Vulnerable to Kerberoasting Attack

是由 Joy Liao3 個月 前加入. 於 約 2 個月 前更新.

狀態:
Resolved-解决
優先權:
Normal
被分派者:
分類:
-
開始日期:
2025-08-01
完成日期:
2025-12-31 (逾期 25 天)
完成百分比:

100%

預估工時:

概述

NN "4.3.2

MITRE-T1558

" "Domain Admin Vulnerable to Kerberoasting Attack

It is possible to obtain the encrypted Kerberos service ticket of a domain admin for offline password cracking.

" "The exposure of encrypted service ticket empowers adversary to reveal the exact password to perform user impersonation or privilege escalation in this case.

It is noteworthy that the affected domain admin has never expiring password and has its password remain unchanged more than 2 years. This allows adversary ample time to perform offline cracking of its password.

" "Avoid assigning SPNs to Domain Admin accounts unless absolutely necessary.

Set long and complex passwords for service accounts and limit privileges of service accounts. If possible, use AES encryption instead of RC4 encryption."


檔案

動作

匯出至 Atom PDF